Vulnerability Bulletins |
Ejecución remota de código en Cisco IOS 12.4 |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Experto |
| Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
| Property | Value |
| Affected manufacturer | Networking |
| Affected software | Cisco IOS 12.4XW, 12.4XY, 12.4XZ y 12.4YA |
Description |
|
|
Se ha descubierto una vulnerabilidad de tipo desbordamiento de búfer en Cisco IOS 12.4. La vulnerabilidad reside en un error en el componente Unified Communications Manager Express (CME). Un atacante remoto podría ejecutar código arbitrario o causar una denegación de servicio mediante peticiones HTTP especialmente diseñados. |
|
Solution |
|
|
Actualización de software Cisco Ver tabla de actualizaciones en http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8116.shtml |
|
Standar resources |
|
| Property | Value |
| CVE | CVE-2009-2865 |
| BID | 36498 |
Other resources |
|
|
Cisco Security Advisory (cisco-sa-20090923-cme) http://www.cisco.com/warp/public/707/cisco-sa-20090923-cme.shtml |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2009-10-23 |






